CVE-2026-86474

Summary

The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.

Affected Software

VendorProductVersion RangeStatus
Fermax Electronica S.A.U.DUOX PLUS monitor firmware (VEO Wi-Fi range)0 < 01.48.001affected

Weaknesses

  • CWE-295: CWE-295 Improper Certificate Validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References